EXPOSURE LM Studio
SEVERITY HIGH
PROBE GET :1234/api/v0/models
Is your LM Studio exposed?
Local OpenAI-compatible API bound to the network: free inference on your hardware.
Scan a host you own → Fix card
Why it matters
LM Studio's OpenAI-compatible API is meant for localhost. On the public internet, strangers can list and run your local models on your hardware.
How common is it?
A published population estimate for LM Studio is still collecting. See the census methodology.
Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.
Fix it
The full walkthrough lives on the fix card, kept current in one place: